Executive brief
A security vulnerability exists in the Windows Network File System (NFS), a component used to share files between computers over a network. An authorized user on the network could exploit this flaw to gain higher-level system permissions than they should have. This could allow an attacker to take full control of the affected server or workstation, potentially leading to data theft or service disruption.
Technical details
A heap-based buffer overflow vulnerability exists in the Windows Network File System (NFS) service. The flaw is rooted in an integer overflow or wraparound (CWE-190) that leads to a heap-based buffer overflow (CWE-122). An attacker with low-privileged network access can exploit this vulnerability without user interaction to achieve elevated privileges on the target system. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server 2012. Microsoft has released security updates to address this issue; administrators should apply the latest cumulative updates for their respective OS versions.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All versions
Timeline
- 2026-07-14: disclosed: Initial publication by Microsoft and NVD